an XSS vulnerability in the navigation tree (https://www.phpmyadmin.net/security/PMASA-2018-8/)

In addition to the security fixes, this release also includes these bug fixes and more as part of our regular release cycle:

Issue with changing theme

Ensure that database names with a dot ('.') are handled properly when DisableIS is true

Fix for message "Error while copying database (pma__column_info)"

Move operation causes "SELECT * FROM `undefined`" error

When logging with $cfg['AuthLog'] to syslog, successful login messages were not logged when $cfg['AuthLogSuccess'] was true

Multiple errors and regressions with Designer

And several more. Complete notes are in the ChangeLog file included with this release.

Note that for this release, we experimented with a pre-release announcement so that hosting providers and package managers would have an opportunity to prepare for the security release. If this was helpful to you or if you have feedback about this technique, please let us know through the public list developers@phpmyadmin.net or privately at security@phpmyadmin.net. We may or may not decide use this behavior in the future and your feedback will help us decide whether it's beneficial to the community.

As always, downloads are available at https://www.phpmyadmin.net/downloads/

The phpMyAdmin project is announcing an upcoming security release. We feel this vulnerability is significant enough to make this announcement in advance. Our intention is to release the download for version 4.8.4 on Tuesday (December 11) at approximately 1400-1500 UTC.

Details about the vulnerabilities will be provided at the time of release. Users, package managers, and others with questions or concerns can reach the security team in private at security@phpmyadmin.net.

The phpMyAdmin team is pleased to announce the release of phpMyAdmin version 4.8.3. Among other bug fixes, this contains a security fix for an issue that can be exploited when importing files.

A flaw was discovered with how warning messages are displayed while importing a file. This attack requires a specially-crafted file but can allow an attacker to trick the user in to executing a cross-site scripting (XSS) attack. We recommend updating immediately to mitigate this attack.

In addition to the security fixes, this release also includes these bug fixes and more as part of our regular release cycle:

The phpMyAdmin team is pleased to announce the release of phpMyAdmin version 4.8.2. Among other bug fixes, this contains an important security update and it is highly recommended that all users upgrade immediately.

The urgent vulnerability allows an authenticated attacker to exploit a phpMyAdmin feature to show and potentially execute files on the server. PHP open_basedir restrictions mitigate the effect of this flaw. For further details, see the PMASA announcement.

In addition to the security fixes, this release also includes these bug fixes as part of our regular release cycle:

WHERE 0 clause causes a fatal error

Fix missing "INDEX" icon

Known issues:

Unable to log in with MySQL 8.0.11 (bug #14220, see also https://bugs.php.net/bug.php?id=76243)

A few users have reported being unable to log in with a persistent error message "Failed to set session cookie. Maybe you are using HTTP instead of HTTPS". In some cases, clearing the phpMyAdmin cookies ('pma*') resolves the issue.

A complete list of changes and bugs fixed is available from the ChangeLog file or changelog.php included with this release.

A few highlights of bugs fixed include:

Fix to the scrollbar functionality and Browse table CSS overflow

Dropping indexes and keys fails

Show two factor (2FA) secret code next to QR image

Configuration for DefaultLang and Lang

MariaDB 10.2 'current_timestamp()'

Remember table sorting is broken

Known issues:

Unable to log in with MySQL 8.0.11 (bug #14220, see also https://bugs.php.net/bug.php?id=76243)

A few users have reported being unable to log in with a persistent error message "Failed to set session cookie. Maybe you are using HTTP instead of HTTPS". In some cases, clearing the phpMyAdmin cookies ('pma*') resolves the issue.

The phpMyAdmin project is please to announce the students and projects that have been selected for participation in Google Summer of Code 2018.

This year the final selections were exceptionally difficult; we received applications from many students that were worthy of being selected. We wish the best to the students who were not selected and hope they'll continue to stay involved and apply again next year.

The students and projects are:

Lakshya Arora, working on general improvements and project enhancements

Google Summer of Code is sponsored by Google and allows college students the opportunity to get paid for work on real-world projects during the summer. The phpMyAdmin project has participated for many years and many new features and enhancements have been incorporated thanks to the work of these students. For more information on GSoC, see their website https://summerofcode.withgoogle.com/.

Welcome to phpMyAdmin 4.8.0.1, which fixes a security flaw found in phpMyAdmin.

This version fixes a security flaw found in version 4.8.0 where an attacker can manipulate
a user in to following a specially-crafted link, allowing the attacker to execute arbitrary
SQL commands on the server. For more information, please see https://www.phpmyadmin.net/security/PMASA-2018-2/

Welcome to phpMyAdmin version 4.8.0. We are excited to bring you this updated version with many new features and bug fixes. There are no changes to system requirements.

A complete list of new features and bugs that have been fixed is available in the ChangeLog file or changelog.php included with this release.

Major changes include security enhancements such as removing the PHP eval() function and authentication logging, a mobile interface to improve the interface when used with tablets or mobile phones, and two-factor authentication options.

Much of this work is thanks to the hard work of our Google Summer of Code 2017 students.

Additionally, there have been continuous improvements to many of the translations. If you don't see your language or find a problem, you can contribute too; see https://www.phpmyadmin.net/translate/ for details.

The remaining notes are for changes from the 4.7.x branch to 4.8.0 and also applied to 4.8.0-alpha1.

Major changes include security enhancements such as removing the PHP eval() function and authentication logging, a mobile interface to improve the interface when used with tablets or mobile phones, and two-factor authentication options.

Additionally, there have been continuous improvements to many of the translations. If you don't see your language or find a problem, you can contribute too; see https://www.phpmyadmin.net/translate/ for details.